Talent.com
IFS
Senior Lead Application Security EngineerIFS • Winnipeg, Canada
Senior Lead Application Security Engineer

Senior Lead Application Security Engineer

IFS • Winnipeg, Canada
3 days ago
Job type
  • Permanent
Job description
IFS is a billion-dollar revenue company with 7000+ employees on all continents. Our leading AI technology is the backbone of our award-winning enterprise software solutions, enabling our customers to be their best when it really matters–at the Moment of Service. Our commitment to internal AI adoption has allowed us to stay at the forefront of technological advancements, ensuring our colleagues can unlock their creativity and productivity, and our solutions are always cutting‑edge. At IFS, we’re flexible, we’re innovative, and we’re focused not only on how we can engage with our customers but on how we can make a real change and have a worldwide impact. We help solve some of society’s greatest challenges, fostering a better future through our agility, collaboration, and trust. We celebrate diversity and understand our responsibility to reflect the diverse world we work in. We are committed to promoting an inclusive workforce that fully represents the many different cultures, backgrounds, and viewpoints of our customers, our partners, and our communities. As a truly international company serving people from around the globe, we realize that our success is tantamount to the respect we have for those different points of view. By joining our team, you will have the opportunity to be part of a

global, diverse environment;

you will be joining a

winning team

with a

commitment to sustainability;

and a company where we get things done so that you can

make a positive impact

on the world. We’re looking for innovative and original thinkers to work in an environment where you can

#MakeYourMoment

so that we can help others make theirs. With the power of our AI-driven solutions, we empower our team to change the status quo and make a real difference. If you want to change the status quo, we’ll help you make your moment. Join Team Purple. Join IFS. Job Description

We are looking for an Application Security Engineer to join the Agentic Platform pillar, working within the Cloud Platform team. This team owns the secure, governed foundation that enables all of Copperleaf’s R&D teams to build and ship faster. In this role you will embed security directly into the platform and across every CI/CD pipeline, shifting our posture from reactive to proactive. You will bring traditional application security depth into our DevSecOps culture and, critically, use AI agents to continuously and autonomously improve our security posture. Our operating premise is simple: agentic attacks require agentic defense. You will build the agents, skills, and guardrails that detect, triage, and remediate security risk at machine speed, staying ahead of threats rather than responding to them after the fact. This is a hands‑on, implementation-first role: you will personally build, ship, and operate the security changes you design, working directly in the code and the pipelines rather than advising from the sidelines. Key Responsibilities

Embed application security into the Cloud Platform and across all CI/CD pipelines, making secure‑by‑default the path of least resistance for every R&D team. Design, build, and operate AI‑driven security agents that proactively scan, triage, and remediate vulnerabilities across source code, dependencies, containers, and infrastructure‑as‑code, turning point‑in‑time reviews into continuous, autonomous coverage. Establish secure software development lifecycle (SSDLC) practices, threat modeling, and secure‑coding standards, and integrate automated enforcement (SAST, SCA, DAST, secrets scanning, IaC scanning) as native pipeline gates rather than bolt‑on checks. Lead the security of our own agentic systems: defend against prompt injection, tool/MCP abuse, data exfiltration, excessive agency, and supply‑chain risk in line with frameworks such as the OWASP Top 10 for LLM Applications and MITRE ATLAS. Drive proactive vulnerability management: remediate HIGH and CRITICAL CVEs across platform infrastructure and container images in line with contractual and compliance commitments, and automate the toil out of it. Partner with engineering teams to harden Azure Kubernetes Service (AKS) workloads, identity and access (Keycloak, Azure AD, Managed Identities, workload identity), network segmentation, and secrets management. Contribute security evidence and controls to compliance programs (SOC 2, ISO 27001, Cyber Insurance), and automate evidence collection and continuous control monitoring with agentic tooling. Define and maintain security runbooks, detection logic, and incident response procedures, and build the agents that execute and accelerate them. Act as the security skill set within the platform team raising the bar through code review, pairing, and sharing pragmatic, developer‑friendly guidance. Contribute to improving the Agentic Operating Model through development of security‑focused agent skills, prompts, and tooling that other teams can reuse. Technical Focus Areas

Application security fundamentals: secure SDLC, threat modeling, OWASP Top 10, secure code review, and remediation across multiple languages and stacks. Agentic and AI security: securing LLM‑and agent‑based systems (prompt injection, tool/MCP security, sandboxing, guardrails), plus building autonomous agents that perform security work. OWASP Top 10 for LLMs and MITRE ATLAS a strong asset. DevSecOps and pipeline security with Azure DevOps: SAST, SCA, DAST, secrets and IaC scanning, SBOM generation, container signing and attestation, and pipeline access controls. Security scanning and tooling: Mend (SCA/SAST), Azure Defender for Cloud, and MDR/SOC platforms. Hands‑on with modern agentic and AI‑security tooling: agentic coding and security assistants (e.g. Claude Code with custom agent skills and MCP), AI‑assisted code analysis and autofix (e.g. Semgrep, Snyk / DeepCode AI, GitHub Copilot Autofix / CodeQL), LLM and agent red‑teaming (e.g. garak, Microsoft PyRIT, Promptfoo), and runtime guardrails and model supply‑chain protection (e.g. Lakera Guard, NVIDIA NeMo Guardrails, Protect AI). Cloud‑native security on Azure Kubernetes Service (AKS): RBAC, network policies, admission controllers (e.g. Kyverno), workload identity, and cluster hardening. Identity and access management: Keycloak, Azure Active Directory, Managed Identities, and secrets management (e.g. CSI secrets driver, Key Vault). Infrastructure‑as‑code: Bicep or Terraform for security configuration, policy‑as‑code, and drift management. Compliance frameworks and automated evidence collection: SOC 2, ISO 27001, and Cyber Insurance requirements. Scripting and automation (e.g. Python, PowerShell, or C#) to build security tooling and orchestrate agents. Qualifications

Area of specialization:

Application Security & DevSecOps – Agentic Defense About You

You think proactively: you anticipate how systems will be attacked and build defenses ahead of the threat, rather than waiting to respond. You are a do-er, not just an advisor: you implement the fixes yourself and measure success by what ships and what is provably more secure, not by recommendations handed to someone else. You demonstrate strong ownership of technical outcomes and a commitment to quality. You apply sound engineering judgment when making design and implementation decisions, balancing security rigor with developer velocity. You communicate clearly and effectively with both technical and non‑technical stakeholders. You continuously develop technical and domain expertise in application security, cloud security, and the rapidly evolving field of agentic/AI security. You collaborate effectively within cross‑functional, outcome‑oriented teams. You leverage AI to accelerate projects and improve overall quality of output, and you are excited to push the frontier of what agentic defense can do. What We’re Offering

Salary Range: $117,000 CAD - $167,000 CAD Permanent, Full‑time Use of Artificial Intelligence in Recruitment

As part of our recruitment process, we may use automated tools, including artificial intelligence, to help screen and assess applications based on job‑related criteria such as skills, experience, and qualifications. These tools do not make hiring decisions. All employment decisions are reviewed and made by members of our hiring team. We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.

#J-18808-Ljbffr
Create a job alert for this search

Senior Lead Application Security Engineer • Winnipeg, Canada

Similar jobs

Senior SecOps Engineer - Cloud Security & Automation

CohereWinnipeg, MB, CA
Full-time

A leading AI research company in Montreal is seeking a Senior Security Operations Engineer to enhance its cloud security efforts.You will manage security protocols, respond to incidents, and work o... Show more

 • Promoted

Cybersecurity Best Practices Specialist New Flyer

JobtailorWinnipeg, MB, CA
Full-time

Advance as a Vehicle Cybersecurity Design Specialist at New Flyer, shaping best practices in vehicle cybersecurity aligned with ISO 21434 standards.Drive the design process from inception to implem... Show more

 • Promoted

Application Security Analyst

407 EtrWinnipeg, Canada
Full-time

Elevate application security at 407 ETR by becoming an Application Security Analyst.Focus on SDLC integration and secure coding practices with a hands-on emphasis on security tooling.In this critic... Show more

 • Promoted

Senior Product Security Engineer - $150,000 - $200,000 A Year - Remote

AffirmWinnipeg, Canada
Remote
Full-time

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.Affirm values information... Show more

 • Promoted

Senior Analyst, Security Compliance

P2PWinnipeg, Manitoba, Canada
Full-time

Building the Future of Crypto Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a... Show more

 • Promoted

Remote Technical Marketing Lead for Security & Dev

Internetwork ExpertWinnipeg, MB, CA
Remote
Full-time

A technology firm is seeking a Technical Marketing Leader to create compelling product narratives and technical content.This remote role requires a strong engineering background and experience in t... Show more

 • Promoted

Senior Security Operations Engineer

CohereWinnipeg, MB, CA
Full-time

Our mission is to scale intelligence to serve humanity.We’re training and deploying frontier models for developers and enterprises who are building AI systems to power magical experiences like cont... Show more

 • Promoted

Azure & Aws Cloud Security Engineer - $120,000 - $180,000 A Year

A leading bankWinnipeg, Canada
Full-time

Cloud Security Engineer at ServiceNow to lead cloud security efforts, focusing on AI integrations and client concerns.Involves customer engagement, presentations, and improving security strategy. Show more

 • Promoted

Architectural Lead For Security & Defence Regionally

Architecture49Winnipeg, Canada
Full-time

Architecture49 seeks a Regional Security & Defence Lead Architect in Winnipeg, MB.Bring your leadership skills to a role focused on the development of high-security infrastructure projects.As t... Show more

 • Promoted

Cyber Security - Systems Security Engineer - $130,000 - $165,000 A Year

49NorthWinnipeg, Canada
Full-time

Seeking a Systems Security Engineer for a Canadian defense company to consult on system architectures, develop security requirements, and oversee security verification.Responsibilities include thre... Show more

 • Promoted

Architectural Lead for Security & Defence Regionally

Architecture49winnipeg, mb, Canada
Full-time

Architecture49 seeks a Regional Security & Defence Lead Architect in Winnipeg, MB.Bring your leadership skills to a role focused on the development of high-security infrastructure projects.As the R... Show more

 • Promoted

Senior Security Engineer

CSC-GeneratioWinnipeg, Manitoba, Canada
Full-time

Join a team that celebrates a lifestyle as bold as the terrain we love.At Backcountry, we are rooted in adventure, recognition, and wellbeing on and off the mountain.We spotlight employee stories, ... Show more

 • Promoted

Application Security Analyst - C$95,000 - C$115,000 A Year

407 EtrWinnipeg, Canada
Full-time

Elevate application security at 407 ETR by becoming an Application Security Analyst.Focus on SDLC integration and secure coding practices with a hands-on emphasis on security tooling.In this critic... Show more

 • Promoted

Senior Cyber Security Engineer – Cloud & Incident Response

Manitoba Liquor & Lotteries CorporationWinnipeg, MB, CA
Full-time

A government-owned corporation in Winnipeg is seeking a Cyber Security Engineer responsible for protecting its systems from cyber threats.This role involves designing security solutions, implementi... Show more

 • Promoted

Senior Technical Implementations Lead

SRA GroupWinnipeg, MB, CA
Permanent

Technical Implementations Lead.Healthcare Technology / Software.SRA Staffing is hiring a full-time.Technical Implementations Lead.This role plays a key part in customer success and technical delive... Show more

 • Promoted

Enterprise Technical Team Lead - C$120,000 - C$130,000 A Year

AMTRA SolutionsWinnipeg, Canada
Full-time

Lead a technical team in managed services, focusing on cloud security and endpoint operations.Responsibilities include incident response, technical guidance, client engagement, and process improvem... Show more

 • Promoted

Cyber Security Engineer

Manitoba Liquor & Lotteries CorporationWinnipeg, MB, CA
Full-time

The Cyber Security Engineer is responsible for the planning, development, design, execution, and support of the operation and integration of cyber security tools and processes to protect Manitoba L... Show more

 • Promoted

Azure Cloud Security Architect – Zero-Trust Leader

A leading technology firmWinnipeg, Canada
Full-time

Cloud Security Architect specializing in Threat Modeling and DevSecOps to secure AI and cloud environments.Requires expertise in AI, ML, cybersecurity, AWS/GCP, and Java/JavaScript. Show more

 • Promoted

Senior Product Security Engineer – Remote Canada - Equity - $150,000 - $200,000 A Year - Remote

Financial Technology FirmWinnipeg, Canada
Remote
Full-time

Seeking a Senior Product Security Engineer for a remote role in Canada to integrate security into product development and address vulnerabilities, requiring software architecture knowledge and clou... Show more

 • Promoted

Cyber Security - Systems Security Engineer

49NorthWinnipeg, Canada
Full-time

Seeking a Systems Security Engineer for a Canadian defense company to consult on system architectures, develop security requirements, and oversee security verification.Responsibilities include thre... Show more